Microsoft Office Web Apps
By the Year
In 2023 there have been 1 vulnerability in Microsoft Office Web Apps with an average score of 9.8 out of ten. Last year Office Web Apps had 2 security vulnerabilities published. Right now, Office Web Apps is on track to have less security vulnerabilities in 2023 than it did last year. However, the average CVE base score of the vulnerabilities in 2023 is greater by 2.65.
Year | Vulnerabilities | Average Score |
---|---|---|
2023 | 1 | 9.80 |
2022 | 2 | 7.15 |
2021 | 12 | 7.80 |
2020 | 23 | 7.44 |
2019 | 2 | 7.80 |
2018 | 10 | 7.08 |
It may take a day or so for new Office Web Apps vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Microsoft Office Web Apps Security Vulnerabilities
Microsoft Word Remote Code Execution Vulnerability
CVE-2023-21716
9.8 - Critical
- February 14, 2023
Microsoft Word Remote Code Execution Vulnerability
Microsoft Excel Information Disclosure Vulnerability
CVE-2022-22716
5.5 - Medium
- February 09, 2022
Microsoft Excel Information Disclosure Vulnerability
Buffer Overflow
Microsoft Office Remote Code Execution Vulnerability.
CVE-2022-21840
8.8 - High
- January 11, 2022
Microsoft Office Remote Code Execution Vulnerability.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-43256
7.8 - High
- December 15, 2021
Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-38655
7.8 - High
- September 15, 2021
Microsoft Excel Remote Code Execution Vulnerability
Dangling pointer
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-28453
7.8 - High
- April 13, 2021
Microsoft Word Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-27057
7.8 - High
- March 11, 2021
Microsoft Office Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24108, CVE-2021-27059.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27054
7.8 - High
- March 11, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-27053.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-27053
7.8 - High
- March 11, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-27054.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24070
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24067, CVE-2021-24068, CVE-2021-24069.
Dangling pointer
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24069
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24067, CVE-2021-24068, CVE-2021-24070.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24068
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24067, CVE-2021-24069, CVE-2021-24070.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2021-24067
7.8 - High
- February 25, 2021
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-24068, CVE-2021-24069, CVE-2021-24070.
Dangling pointer
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-1716
7.8 - High
- January 12, 2021
Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1715.
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-1715
7.8 - High
- January 12, 2021
Microsoft Word Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-1716.
Memory Corruption
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17129
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17128
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17129.
Microsoft Excel Information Disclosure Vulnerability
CVE-2020-17126
5.5 - Medium
- December 10, 2020
Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17125
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17123, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17123
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17122, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17122
7.8 - High
- December 10, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17123, CVE-2020-17125, CVE-2020-17127, CVE-2020-17128, CVE-2020-17129.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17065
7.8 - High
- November 11, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17019, CVE-2020-17064, CVE-2020-17066.
Microsoft Excel Remote Code Execution Vulnerability
CVE-2020-17064
7.8 - High
- November 11, 2020
Microsoft Excel Remote Code Execution Vulnerability This CVE ID is unique from CVE-2020-17019, CVE-2020-17065, CVE-2020-17066.
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16932
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16929, CVE-2020-16930, CVE-2020-16931.
Buffer Overflow
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16931
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16929, CVE-2020-16930, CVE-2020-16932.
Use of Uninitialized Resource
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-16929
7.8 - High
- October 16, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-16930, CVE-2020-16931, CVE-2020-16932.
Dangling pointer
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory
CVE-2020-1335
8.8 - High
- September 11, 2020
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1193, CVE-2020-1332, CVE-2020-1594.
Buffer Overflow
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2020-1218
8.8 - High
- September 11, 2020
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1338.
Code Injection
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory
CVE-2020-1224
5.5 - Medium
- September 11, 2020
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
Information Disclosure
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory
CVE-2020-1583
5.5 - Medium
- August 17, 2020
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1503.
Information Disclosure
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory
CVE-2020-1503
5.5 - Medium
- August 17, 2020
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory, aka 'Microsoft Word Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1502, CVE-2020-1583.
Information Disclosure
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2020-1448
8.8 - High
- July 14, 2020
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
Buffer Overflow
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2020-1447
8.8 - High
- July 14, 2020
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
Buffer Overflow
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2020-1446
8.8 - High
- July 14, 2020
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Buffer Overflow
A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request
CVE-2020-1442
6.1 - Medium
- July 14, 2020
A spoofing vulnerability exists when an Office Web Apps server does not properly sanitize a specially crafted request, aka 'Office Web Apps XSS Vulnerability'.
XSS
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable
CVE-2020-1342
5.5 - Medium
- July 14, 2020
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
Use of Uninitialized Resource
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2020-0980
7.8 - High
- April 15, 2020
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Buffer Overflow
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2020-0892
7.8 - High
- March 12, 2020
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
Buffer Overflow
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2019-1201
7.8 - High
- August 14, 2019
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1205.
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2019-1034
7.8 - High
- June 12, 2019
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1035.
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory
CVE-2018-8628
7.8 - High
- December 12, 2018
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft SharePoint Server.
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory
CVE-2018-8539
7.8 - High
- November 14, 2018
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Microsoft Office. This CVE ID is unique from CVE-2018-8573.
A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View
CVE-2018-8504
8.8 - High
- October 10, 2018
A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable
CVE-2018-8378
5.5 - Medium
- August 15, 2018
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.
Use of Uninitialized Resource
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests
CVE-2018-8247
5.4 - Medium
- June 14, 2018
An elevation of privilege vulnerability exists when Office Web Apps Server 2013 and Office Online Server fail to properly handle web requests, aka "Microsoft Office Elevation of Privilege Vulnerability." This affects Microsoft Office, Microsoft Office Online Server. This CVE ID is unique from CVE-2018-8245.
XSS
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory
CVE-2018-8161
7.8 - High
- May 09, 2018
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157, CVE-2018-8158.
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts
CVE-2018-1028
8.8 - High
- April 12, 2018
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
Code Injection
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Compatibility Pack SP2, Microsoft Online Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2007 SP3, Microsoft Word 2010 SP2, Word 2013 and Microsoft Word 2016
CVE-2018-0922
7.8 - High
- March 14, 2018
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Compatibility Pack SP2, Microsoft Online Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2007 SP3, Microsoft Word 2010 SP2, Word 2013 and Microsoft Word 2016 allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
Memory Corruption
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016
CVE-2018-0919
3.3 - Low
- March 14, 2018
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016 allow an information disclosure vulnerability due to how variables are initialized, aka "Microsoft Office Information Disclosure Vulnerability".
Use of Uninitialized Resource
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016
CVE-2018-0797
7.8 - High
- January 10, 2018
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
Memory Corruption
A remote code execution vulnerability exists in Excel Services
CVE-2017-8631
7.8 - High
- September 13, 2017
A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Web App 2013 Service Pack 1, Microsoft Excel Viewer 2007 Service Pack 3, and Office Online Server when they fail to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8630, CVE-2017-8632, and CVE-2017-8744.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Microsoft Office Web Apps or by Microsoft? Click the Watch button to subscribe.
